Monitor of IPSec tunnel

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Monitor of IPSec tunnel

L4 Transporter

What is the best way to monitor an IPSec tunnel on the PA, I don't see anything in the traffic logs at all just the systeme logs

7 REPLIES 7

Cyber Elite
Cyber Elite

Hello,

What are you attempting to monitor, like up down status?

 

Regards,

@OtakarKlier

 

No thats the easy part knowing if it is up or down, just watch the green balls LOL. I guess I was hoping to see something in the traffic logs but technically I probably have an encrypted tunnel that by passes all that and come right into the network.  Guess I am checking to make sure that is normal and I have it set up correctly

Hello,

If your PAN is the ipsec endpoint, then it will see the decrypted traffic. What I do is alwyas have the tunnel a different zone so I can create policies around the traffic. Also I can watch the traffic by selecting the source and destination zones.

 

Regards,

@OtakarKlier

I created a rule to let the traffic in but when I search by the rule it shows no traffic passing on it so to speak though it is clearly being hit.  I don't use panorama at all if that is why you are referring to as PAN

Try searching by a known IP address on the tunnel as the source and see which policy it is hitting.

@OtakarKlier

 

Nothing

Maybe as destiantion and ping it so you can see traffic? Perhaps there is no traffic going over it (long shot I know).

  • 2593 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!